PT-2011-1350 · Pentaho · Pentaho Bi Server

Published

2011-09-13

·

Updated

2018-10-10

·

CVE-2009-5101

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pentaho BI Server versions 1.7.0.1062 and earlier
Description The issue allows attackers to obtain the session ID (JSESSIONID) from session history, referer headers, or by sniffing web traffic, as it is included in the URL.
Recommendations For Pentaho BI Server versions 1.7.0.1062 and earlier, consider configuring the server to no longer include the session ID in the URL to prevent unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-5101

Affected Products

Pentaho Bi Server